PT-2026-79646 · Linux · Linux Kernel

CVE-2026-74641

·

Published

2026-08-22

·

Updated

2026-08-27

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the ALSA usx2y component where the snd us428ctls vm fault() function converts a faulting page offset into a kernel address without performing any boundary checks. Because snd us428ctls mmap() only verifies the mapping length and not the offset, and the memory management layer imposes no ceiling for character devices, a user can provide a page offset above zero to resolve a page outside the intended object. This allows a process that can open the hwdep node of an attached US-X2Y device to gain read-write access to kernel memory it does not own. If the offset points to an unpopulated vmemmap region, it results in a kernel oops. The same issue affects the pcm hwdep handler in usx2yhwdeppcm.c.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-74641

Affected Products

Linux Kernel